Hi Guys,
Wasn't sure the appropriate forum to post this so I'm hoping this will do.
I've just been running some network audits on my home LAN and noticed in the nessus scan reporting a (most likely) default configuration issue that need attention.
--
Web Server Directory Traversal Arbitrary File Access
Synopsis The remote web server is affected by a directory traversal vulnerability.Description
It appears possible to read arbitrary files on the remote host outside the web server’s document directory using a specially crafted URL. An unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks.Note that this plugin is not limited to testing for known vulnerabilities in a specific set of web servers. Instead, it attempts a variety of generic directory traversal attacks and considers a product to be vulnerable simply if it finds evidence of the contents of ‘/etc/passwd’ or a Windows ‘win.ini’ file in the response. It may, in fact, uncover ‘new’ issues, that have yet to be reported to the product’s vendor.
Solution
Contact the vendor for an update, use a different product, or disable the service altogether.
Plugin Information Plugin ID: 10297 Plugin Version: $Revision: 1.104 $ Plugin Type: remote Plugin Publication Date: 1999/11/05 Plugin Last Modification Date: 2013/04/04
Risk Information Risk Factor: Medium CVSS Base Score: 5.0 CVSS Vector Score: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N CVSS Temporal Vector: CVSS2#E:F/RL:OF/RC:C CVSS Temporal Score: 4.1
Vulnerability Information Exploit Available: true Exploitability Ease: Exploits are available Exploitable With: Metasploit (Indusoft WebStudio NTWebServer Remote File Access)
Reference Information
cve: CVE-2013-2619 CVE-2012-5641 CVE-2012-5344 CVE-2012-5335 CVE-2012-5100 CVE-2012-1464 CVE-2012-0697 CVE-2011-4788 CVE-2011-2524 CVE-2011-1900 CVE-2010-4181 CVE-2010-3743 CVE-2010-3488 CVE-2010-3487 CVE-2010-3459 CVE-2010-1571 CVE-2008-5315 CVE-2000-0920
osvdb: 89293 88925 82678 82647 80586 79653 78308 78307 74135 73413 72972 72498 72231 70176 68962 68880 68538 68141 68089 68026 65285 64611 64532 50288 3681
bid: 58794 57313 57143 56871 52541 52327 51399 51311 48926 48114 47987 47842 47760 45603 45599 44586 44564 44393 43830 43358 43356 43258 43230 40680 40133 40053 32412 7715 7544 7378 7362 7308
edb-id: 24915
Plugin Output3000 / tcp
Service: www
Nessus was able to retrieve the remote host’s password file using the following URL :
http://lounge-room-mac-mini.local.:3000/../../../../../../../../../../../../etc/passwd
Here are the contents : ------------------------------ snip ------------------------------ ## # User Database # # Note that this file is consulted directly only when the system is running # in single-user mode. At other times this information is provided by # Open Directory. # # See the opendirectoryd(8) man page for additional information about # Open Directory. ## nobody:*:-2:-2:Unprivileged User:/var/empty:/usr/bin/false root:*:0:0:System Administrator:/var/root:/bin/sh etc...